ULiveServer.exe

UMediaServer

Unreal Streaming Technologies

The executable ULiveServer.exe, “Live media server.” has been detected as malware by 3 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “ULiveServer”.
Publisher:
Unreal Streaming Technologies.  (signed by Unreal Streaming Technologies)

Product:
UMediaServer

Description:
Live media server.

Version:
9.5.0.155

MD5:
d15cbca3e60694e9a969e4554be926c5

SHA-1:
447e9ca2c1bb2464d138134907aad9dda393873a

SHA-256:
8420ab1ce0641e59f4483b00dea1f4d79f6b848224b461b847e94327131ebef2

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/9/2024 1:45:07 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
389.1 KB (398,439 bytes)

Product version:
9.5.0.155

Copyright:
Copyright (C) 2002-2012 by Unreal Streaming Technologies

Original file name:
ULiveServer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\unrealstreaming\uliveserver\uliveserver.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/31/2014 6:00:00 AM

Valid to:
4/20/2016 5:59:59 AM

Subject:
CN=Unreal Streaming Technologies, OU=Software Development, O=Unreal Streaming Technologies, L=Doraville, S=Georgia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
49004D1F8A15664020CFED086B13DAA9

File PE Metadata
Compilation timestamp:
5/19/2015 11:12:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:3uNnsXvWpOz4jD52ij0VmTCTIBjvrEH76:+zpFjD5d22rEH76

Entry address:
0x12CCD

Entry point:
E9, F0, A2, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, D8, 84, 44, 00, 00, 74, 05, E9, F7, BD, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01...
 
[+]

Entropy:
6.9263

Packer / compiler:
Xtreme-Protector v1.05

Code size:
215 KB (220,160 bytes)

Service
Display name:
ULiveServer

Description:
Unreal Live Server: encodes, streams and records live audio/video sources.

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove ULiveServer.exe - Powered by Reason Core Security